United States
USA
On 02/07/2021, REvil exploited a zero‑day in KASEYA’s VSA remote management software to distribute ransomware through dozens of MSPs to downstream businesses. Kaseya shut down VSA SaaS and advised on‑prem customers to take servers offline. Sweden’s COOP closed about 800 stores due to POS outages. REvil demanded $70M for a universal decryptor; Kaseya later obtained a universal decryptor from a trusted third party.
Estimated severity
88 / 100
Source reliability
88 / 100
Approximate Date
02/07/2021
Targeted Company
KASEYA
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
United States
USA
Sweden
SWE
Target country
United States
Affected countries
Impacted regions
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Please rotate your phone